CVE List

cve编号 漏洞描述 危险等级 包名 是否影响lns23-3 修复状态 发现时间 修复时间
CVE-2023-33951 A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM o... Moderate kernel 完成修复 2023-07-24 2026-01-07
CVE-2023-32258 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the proc... Important kernel 完成修复 2023-07-24 2025-12-06
CVE-2023-32257 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the proc... Important kernel 完成修复 2023-07-24 2025-12-06
CVE-2023-32252 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the hand... Important kernel 完成修复 2023-07-24 2025-12-06
CVE-2023-32248 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the hand... Important kernel 完成修复 2023-07-24 2025-12-09
CVE-2023-32247 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the hand... Important kernel 完成修复 2023-07-24 2025-12-09
CVE-2023-3019 A DMA reentrancy issue leading to a use-after-free error was found in the e1000e NIC emulation code in QEMU. This issue could a... Moderate qemu, virt:an 完成修复 2023-07-24 2025-12-19
CVE-2023-3773 A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a malicio... Moderate kernel 完成修复 2023-07-23 2026-01-07
CVE-2023-38633 2.56.3之前的librsvg的URL解码器中的目录遍历问题可能会被本地或远程攻击者用来泄露文件(在预期... Moderate librsvg2 完成修复 2023-07-22 2026-07-11
CVE-2023-37450 A vulnerability was found in webkitgtk. This issue occurs when processing web content, which may lead to arbitrary code executi... Important webkit2gtk3 完成修复 2023-07-22 2026-01-04
CVE-2023-32439 A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, Safari 16.5.1, ... Important webkitgtk, webkit2gtk3 完成修复 2023-07-22 2026-01-04
CVE-2023-32435 A memory corruption issue was addressed with improved state management. This issue is fixed in Safari 16.4, iOS 16.4 and iPadOS... Important webkit2gtk3 完成修复 2023-07-22 2026-01-04
CVE-2023-3776 linux内核中的cls_fw模块存在uaf漏洞,fw_set_parms函数中因为错误的执行流,当tcf_change_indev函数发生�... Moderate kernel 完成修复 2023-07-20 2026-01-07
CVE-2023-37650 A Cross-Site Request Forgery (CSRF) in the Admin portal of Cockpit CMS v2.5.2 allows attackers to execute arbitrary Administrat... Important cockpit 完成修复 2023-07-20 2026-01-04
CVE-2023-37649 Incorrect access control in the component /models/Content of Cockpit CMS v2.5.2 allows unauthorized attackers to access sensiti... Important cockpit 完成修复 2023-07-20 2026-01-08
CVE-2023-3812 linux内核的YUN/TAP驱动存在越界,缺乏对数据包的长度做检查导致当数据包过大时,比如大于ETH_MAX... Moderate kernel 完成修复 2023-07-19 2026-01-07
CVE-2023-34968 Samba中发现路径泄露漏洞。作为Spotlight协议的一部分,Samba在搜索查询结果中公开共享、文件和目... Moderate openchange, evolution-mapi, samba 完成修复 2023-07-19 2026-07-10
CVE-2023-34967 Spotlight的SambamdssvcRPC服务中发现类型混淆漏洞。解析SpotlightmdssvcRPC数据包时,一种编码数据结构�... Moderate openchange, evolution-mapi, samba 完成修复 2023-07-19 2026-07-10
CVE-2023-34966 Spotlight的SambamdssvcRPC服务中发现无限循环漏洞。解析客户端发送的SpotlightmdssvcRPC数据包时,核心�... Important openchange, evolution-mapi, samba 完成修复 2023-07-19 2026-01-10
CVE-2023-2828 Every named instance configured to run as a recursive resolver maintains a cache database holding the responses to the querie... Important bind9.16, bind 完成修复 2023-07-19 2026-01-06
CVE-2022-40896 A ReDoS issue was discovered in pygments/lexers/smithy.py in pygments through 2.15.0 via SmithyLexer. Moderate python-pygments 完成修复 2023-07-19 2026-07-10
CVE-2022-2127 由于winbindd_pam_auth_crap.c中的长度检查不足,Samba中发现越界读取漏洞。执行NTLM身份验证时,客户�... Moderate openchange, evolution-mapi, samba 完成修复 2023-07-19 2026-07-10
CVE-2023-38432 An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship... Important kernel 完成修复 2023-07-18 2025-12-05
CVE-2023-38431 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationshi... Critical kernel 完成修复 2023-07-18 2025-12-05
CVE-2023-38430 An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an ou... Critical kernel 完成修复 2023-07-18 2025-12-06
CVE-2023-38429 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allo... Critical kernel 完成修复 2023-07-18 2025-12-06
CVE-2023-38428 An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName valu... Critical kernel 完成修复 2023-07-18 2025-12-06
CVE-2023-38427 An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-... Important kernel 完成修复 2023-07-18 2025-12-06
CVE-2023-38426 An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create... Critical kernel 完成修复 2023-07-18 2025-12-06
CVE-2023-35898 IBM InfoSphere Information Server 11.7 could allow an authenticated user to obtain sensitive information due to an insecure sec... Moderate kernel 完成修复 2023-07-18 2026-01-07
CVE-2023-29260 IBM Sterling Connect:Express for UNIX 1.5 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated ... Moderate kernel 完成修复 2023-07-18 2026-01-07
CVE-2023-29259 IBM Sterling Connect:Express for UNIX 1.5 browser UI is vulnerable to attacks that rely on the use of cookies without the SameS... Moderate kernel 完成修复 2023-07-18 2026-01-07
CVE-2023-22058 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 8... Moderate mysql, mysql:8.0 完成修复 2023-07-18 2026-03-26
CVE-2023-22057 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affect... Moderate mysql, mysql:8.0 完成修复 2023-07-18 2026-03-26
CVE-2023-22056 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2023-07-18 2026-03-26
CVE-2023-22054 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql, mysql:8.0 完成修复 2023-07-18 2026-03-26
CVE-2023-22053 Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected a... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-26
CVE-2023-22048 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Pluggable Auth). Supported versions that are aff... Low mysql:8.0, mysql 完成修复 2023-07-18 2026-03-26
CVE-2023-22046 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-26
CVE-2023-22045 Vulnerability in the Oracle Java SE, Oracle GraalVM Enterprise Edition, Oracle GraalVM for JDK product of Oracle Java SE (compo... Low java-17-openjdk, java-1.8.0-openjdk, java-11-openjdk-portable, java-11-openjdk, java-17-openjdk-portable, java-1.8.0-openjdk-portable 完成修复 2023-07-18 2025-12-05
CVE-2023-22038 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that a... Low mysql:8.0, mysql 完成修复 2023-07-18 2026-03-26
CVE-2023-22033 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-26
CVE-2023-22008 Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.33... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-25
CVE-2023-22007 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affect... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-25
CVE-2023-22005 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affect... Moderate mysql:8.0, mysql 完成修复 2023-07-18 2026-03-25
CVE-2023-21950 Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Replication). Supported versions that are affect... Moderate mysql 完成修复 2023-07-18 2026-03-25
CVE-2022-47085 An issue was discovered in ostree before 2022.7 allows attackers to cause a denial of service or other unspecified impacts via ... Moderate ostree 完成修复 2023-07-18 2026-01-22
CVE-2022-43908 IBM Security Guardium 11.3 could allow an authenticated user to cause a denial of service due to improper input validation. IBM... Moderate kernel 完成修复 2023-07-18 2026-01-07
CVE-2022-41409 Integer overflow vulnerability in pcre2test before 10.41 allows attackers to cause a denial of service or other unspecified imp... Important pcre2 完成修复 2023-07-18 2026-01-09
CVE-2022-33065 Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src... Moderate libsndfile 完成修复 2023-07-18 2026-03-25
CVE-2022-33064 An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows... Important libsndfile 完成修复 2023-07-18 2026-01-08
CVE-2021-38933 IBM Sterling Connect:Direct for UNIX 1.5 uses weaker than expected cryptographic algorithms that could allow an attacker to dec... Important kernel 完成修复 2023-07-18 2025-12-05
CVE-2021-33294 In elfutils 0.183, an infinite loop was found in the function handle_symtab in readelf.c .Which allows attackers to cause a den... Moderate elfutils 完成修复 2023-07-18 2026-03-25
CVE-2023-38473 在avahi_dns_packet_append_record中发现可达断言。 Moderate avahi 完成修复 2023-07-17 2026-03-25
CVE-2023-38472 在avahi_dns_packet_append_record中发现可达断言。 Moderate avahi 完成修复 2023-07-17 2026-03-25
CVE-2023-38471 在avahi_dns_packet_append_record中发现可达断言。 Moderate avahi 完成修复 2023-07-17 2026-03-25
CVE-2023-38470 在avahi_dns_packet_append_record中发现可达断言。 Moderate avahi 完成修复 2023-07-17 2026-03-25
CVE-2023-38469 在avahi_dns_packet_append_record中发现可达断言。 Moderate avahi 完成修复 2023-07-17 2026-03-25
CVE-2023-38409 An issue was discovered in set_con2fb_map in drivers/video/fbdev/core/fbcon.c in the Linux kernel before 6.2.12. Because an ass... Moderate kernel 完成修复 2023-07-17 2026-01-07
CVE-2023-37769 stress-test master commit e4c878 was discovered to contain a FPE vulnerability via the component combine_inner at /pixman-combi... Moderate pixman 完成修复 2023-07-17 2026-03-25
CVE-2023-37211 Memory safety bugs present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12. Some of these bugs showed evidence of me... Important firefox, thunderbird 完成修复 2023-07-17 2025-12-30
CVE-2023-37208 When opening Diagcab files, Firefox did not warn the user that these files may contain malicious code. This vulnerability affec... Moderate firefox, thunderbird 完成修复 2023-07-17 2026-01-24
CVE-2023-37207 A website could have obscured the fullscreen notification by using a URL with a scheme handled by an external program, such as ... Moderate firefox, thunderbird 完成修复 2023-07-17 2026-01-24
CVE-2023-37202 Cross-compartment wrappers wrapping a scripted proxy could have caused objects from other compartments to be stored in the main... Important firefox, thunderbird 完成修复 2023-07-17 2025-12-30
CVE-2023-37201 An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability af... Important firefox, thunderbird 完成修复 2023-07-17 2025-12-30
CVE-2021-31294 Redis before 6cbea7d allows a replica to cause an assertion failure in a primary server by sending a non-administrative command... Moderate redis 完成修复 2023-07-15 2026-01-22
CVE-2023-38325 Python41.0.2之前的加密包会错误地处理具有关键选项的SSH证书。 Important python-cryptography 完成修复 2023-07-14 2025-12-30
CVE-2023-37268 Warpgate is an SSH, HTTPS and MySQL bastion host for Linux that doesn't need special client apps. When logging in as a user wit... Moderate mysql 完成修复 2023-07-14 2026-03-25
CVE-2023-31147 c-ares is an asynchronous resolver library. When /dev/urandom or RtlGenRandom() are unavailable, c-ares uses rand() to generate... Moderate nodejs:18, nodejs:16, c-ares 完成修复 2023-07-14 2026-03-25
CVE-2023-31130 c-ares is an asynchronous resolver library. ares_inet_net_pton() is vulnerable to a buffer underflow for certain ipv6 addresses... Moderate nodejs:18, nodejs, nodejs:16, c-ares 完成修复 2023-07-14 2026-03-25
CVE-2023-31124 c-ares is an asynchronous resolver library. When cross-compiling c-ares and using the autotools build system, CARES_RANDOM_FILE... Low nodejs:18, nodejs:16, c-ares 完成修复 2023-07-14 2026-03-25
CVE-2023-3649 iSCSI dissector crash in Wireshark 4.0.0 to 4.0.6 allows denial of service via packet injection or crafted capture file Moderate wireshark 完成修复 2023-07-13 2026-01-22
CVE-2023-3648 Kafka dissector crash in Wireshark 4.0.0 to 4.0.6 and 3.6.0 to 3.6.14 allows denial of service via packet injection or crafted ... Moderate wireshark 完成修复 2023-07-13 2026-01-22
CVE-2023-35945 Envoy是云原生高性能边缘/中间/服务代理。Envoy的HTTP/2编解码器可能会在从上游服务器接收到RST_STR... Moderate nodejs, nghttp2 完成修复 2023-07-13 2026-07-13
CVE-2023-2975 AES-SIV密码实现包含一个错误,该错误会导致忽略未经身份验证的空关联数据条目。使用AES-SIV算�... Moderate openssl-pkcs11, openssl, shim 完成修复 2023-07-13 2026-03-27
CVE-2023-3610 linux内核的netfilter模块存在uaf漏洞,原因在于nft_data_hole和nft_data_release中对于chain的绑定处理有问�... Important kernel 完成修复 2023-07-12 2025-12-05
CVE-2023-3106 A NULL pointer dereference vulnerability was found in netlink_dump. This issue can occur when the Netlink socket receives the m... Moderate kernel 完成修复 2023-07-12 2026-01-07
CVE-2023-21400 In multiple functions of io_uring.c, there is a possible kernel memory corruption due to improper locking. This could lead to ... Moderate kernel 完成修复 2023-07-12 2026-01-07
CVE-2023-21255 In multiple functions of binder.c, there is a possible memory corruption due to a use after free. This could lead to local esca... Important kernel 完成修复 2023-07-12 2025-12-05
CVE-2022-24834 Redis是一个持久保存在磁盘上的内存数据库。在Redis中执行的特制Lua脚本可能会触发cjson库中的堆�... Important redis, redis:6, python-redis 完成修复 2023-07-12 2026-01-04
CVE-2023-36824 Redis是一个持久保存在磁盘上的内存数据库。在7.0.12之前的Redit7.0中,从命令和参数列表中提取键... Important redis 完成修复 2023-07-11 2026-01-04
CVE-2023-3618 libtiff中发现了一个缺陷。由于libtiff/tif_fax3.c中的Fax3Encode函数中的缓冲区溢出,特制的tiff文件可�... Moderate libtiff 完成修复 2023-07-11 2026-03-25
CVE-2023-3269 A vulnerability exists in the memory management subsystem of the Linux kernel. The lock handling for accessing and updating vir... Important kernel 完成修复 2023-07-11 2025-12-05
CVE-2023-3108 A flaw was found in the subsequent get_user_pages_fast in the Linux kernel’s interface for symmetric key cipher algorithms in... Moderate kernel 完成修复 2023-07-11 2026-01-07
CVE-2023-29406 HTTP/1客户端不完全验证Host标头的内容。恶意制作的Host标头可以注入额外的标头或整个请求。通�... Moderate grafana, golang-dbus, go-toolset:an8, container-tools:an8, golang 完成修复 2023-07-11 2025-12-11
CVE-2023-1672 A race condition exists in the Tang server functionality for key generation and key rotation. This flaw results in a small time... Moderate tang 完成修复 2023-07-11 2026-06-24
CVE-2023-3603 处理读取请求的sftp服务器中缺少分配检查可能会导致在内存不足的情况下出现NULL取消引用。恶�... Moderate libssh, libssh2 完成修复 2023-07-10 2026-03-25
CVE-2023-32250 A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within the proc... Important kernel 完成修复 2023-07-10 2025-12-05
CVE-2023-1183 A flaw was found in the Libreoffice package. An attacker can craft an odb containing a "database/script" file with a SCRIPT com... Moderate libreoffice 完成修复 2023-07-10 2026-07-11
CVE-2023-3576 tiffcrop命令行工具中的内存泄漏 Moderate libtiff 完成修复 2023-07-09 2026-03-25
CVE-2023-3567 linux内核的drivers/tty/vt/vc_screen.c文件中vcs_read存在use-after-free漏洞,在console_unlock之后的极小时差内... Moderate kernel 完成修复 2023-07-09 2026-01-22
CVE-2023-37454 An issue was discovered in the Linux kernel through 6.4.2. A crafted UDF filesystem image causes a use-after-free write operati... Low kernel:4.19, kernel:6.6, kernel:5.10 完成修复 2023-07-06 2026-01-22
CVE-2023-37453 An issue was discovered in the USB subsystem in the Linux kernel through 6.4.2. There is an out-of-bounds and crash in read_des... Moderate kernel 完成修复 2023-07-06 2026-01-07
CVE-2023-29824 DISPUTED A use-after-free issue was discovered in Py_FindObjects() function in SciPy versions prior to 1.8.0. NOTE: the v... Moderate scipy 完成修复 2023-07-06 2026-03-25
CVE-2023-36665 "protobuf.js (aka protobufjs) 6.10.0 through 7.x before 7.2.5 allows Prototype Pollution, a different vulnerability than CVE-20... Moderate ceph 完成修复 2023-07-05 2026-07-13
CVE-2023-30678 Potential zip path traversal vulnerability in Calendar application prior to version 12.4.07.15 in Android 13 allows attackers t... Moderate ocaml-calendar 完成修复 2023-07-05 2026-03-25
CVE-2023-25399 A refcounting issue which leads to potential memory leak was discovered in scipy commit 8627df31ab in Py_FindObjects() function... Moderate scipy 完成修复 2023-07-05 2026-03-25
CVE-2020-25969 gnuplot v5.5 was discovered to contain a buffer overflow via the function plotrequest(). Moderate gnuplot 完成修复 2023-07-05 2026-07-11
CVE-2023-35001 linux内核的nf_tables组件的nft_byteorder_eval函数中因为union的使用,当此时priv->size为2时,虽然下标是�... Important kernel 完成修复 2023-07-04 2025-12-05
CVE-2023-31248 nft_chain_lookup_byid函数忽略了变量genmask,没有判断chain是否已被删除,修复比较简单,在通过id找ch... Important kernel 完成修复 2023-07-04 2025-12-05

第1页 | 上一页| 下一页 | 最后一页

©龙芯开源社区 all right reserved,powered by Gitbook文档更新时间: 2026-08-05 21:34:31

results matching ""

    No results matching ""

    results matching ""

      No results matching ""